Agent SDK hooks: CCAR-F task statement 1.5
CCAR-F · Agentic Architecture & Orchestration (27% of the exam)
Task statement 1.5 sits in Agentic Architecture & Orchestration, 27% of the CCAR-F exam. It tests one decision above all: when a business rule must hold every time, enforce it in code with a hook, not with an instruction in the prompt.
What the official guide covers
The Claude Certified Architect Foundations exam guide (version 1.0, effective July 2026) lists this under task statement 1.5, "Apply Agent SDK hooks for tool call interception and data normalization":
| Knowledge of | Skills in |
|---|---|
| Hooks such as PostToolUse that change tool results before Claude processes them | Writing PostToolUse hooks that convert mixed formats (Unix timestamps, ISO 8601, numeric status codes) from different MCP tools into one format |
| Hooks that intercept outgoing tool calls to enforce rules, such as blocking refunds above a threshold | Writing hooks that block calls breaking a policy, such as refunds over $500, and send them to another workflow such as human escalation |
| Hooks give deterministic guarantees; prompt instructions give probabilistic compliance | Choosing hooks over prompt instructions when a rule must always hold |
What hooks do
A hook is your own function that the Agent SDK runs at a set point in the agent's work. Two hooks matter most for this task statement:
| Hook | Runs | What it can do |
|---|---|---|
PreToolUse | Before a tool runs | Allow, deny or ask for approval (permissionDecision), give Claude the reason (permissionDecisionReason), or change the tool's input (updatedInput) |
PostToolUse | After a tool returns | Replace the result before Claude sees it (updatedToolOutput) or add context to it (additionalContext) |
A matcher chooses which tools a hook applies to, for example "process_refund" or "^mcp__" for every MCP tool. If several hooks match, a deny from any of them blocks the call.
Why the exam prefers hooks for hard rules
An instruction in the system prompt, such as "never refund more than $500", works most of the time. The guide calls this probabilistic compliance. A PreToolUse hook checks every process_refund call in code, so a refund above the limit cannot run. When the question says a rule must hold "every time", "always" or "never", the answer is a hook.
Return a clear reason with every deny. Claude reads permissionDecisionReason, does not retry the blocked call, and can tell the customer what happens next, for example that a person will review the refund.
A refund limit as a hook (Python)
from claude_agent_sdk import ClaudeAgentOptions, HookMatcher
REFUND_LIMIT = 500
async def enforce_refund_limit(input_data, tool_use_id, context):
amount = input_data["tool_input"].get("amount", 0)
if amount > REFUND_LIMIT:
create_review_ticket(input_data["tool_input"]) # your escalation workflow
return {
"hookSpecificOutput": {
"hookEventName": "PreToolUse",
"permissionDecision": "deny",
"permissionDecisionReason": (
f"Refunds over ${REFUND_LIMIT} need human approval. "
"A review ticket has been created."
),
}
}
return {} # allow the call unchanged
options = ClaudeAgentOptions(
hooks={
"PreToolUse": [
HookMatcher(matcher="mcp__billing__process_refund", hooks=[enforce_refund_limit])
]
}
)
The hook runs in your code on every process_refund call. Claude never sees a path around it. A PostToolUse hook follows the same pattern: it reads the tool's result and returns updatedToolOutput with the converted data, so Claude only ever reads the normalised version.
Hook, prompt or permission?
| The requirement | Use | Why |
|---|---|---|
| A rule that must hold every time (refund limits, blocked commands, data that must never leave) | PreToolUse hook | Enforced in code on every call |
| Tool results arrive in mixed formats | PostToolUse hook | Converted before Claude reads them |
| A person should approve some actions case by case | Permission set to ask | The user decides at run time |
| Tone, style or a preferred approach | System prompt | Guidance is enough; occasional misses are acceptable |
Where it appears in the exam
Domain 1 is a primary domain in three of the six exam scenarios: Customer Support Resolution Agent, Multi-Agent Research System and Developer Productivity with Claude. Refund limits and escalation fit the customer support scenario. Normalising data from several tools fits the research scenario.
Two sample questions
These are original Timo practice questions. They are not official exam questions.
Build exercise
- Give an Agent SDK agent a
process_refundtool and add thePreToolUsehook above. - Ask for a $200 refund and a $900 refund. Confirm the first runs and the second is denied with the reason shown to Claude.
- Add a second tool that returns dates as Unix timestamps. Write a
PostToolUsehook that converts them to ISO 8601 and check what Claude reads. - Remove the hook and put the refund limit in the system prompt instead. Run 50 mixed requests and count how often the limit is broken. That count is the difference between probabilistic and deterministic compliance.
Practise this topic
- Claude Certified Architect practice exam: free, 20 questions, no sign-up
- Claude Certified Architect hub
- CCAR-F study guide: all topics
- Worked example: Claude Agent SDK hooks
- Previous topic: 1.4 Workflow enforcement and handoff
- Next topic: 1.6 Task decomposition
Sources
- Claude Certified Architect Foundations Exam Guide, version 1.0, effective July 2026 (Anthropic), task statement 1.5
- Claude Agent SDK documentation: Hooks
- Anthropic: Building effective agents
By Amotion AI